CVE-2026-65831 PUBLISHED

ArcadeDB: Privilege escalation via reader role in /api/v1/command JS scripting language — arbitrary host file read

Assigner: GitHub_M
Reserved: 22.07.2026 Published: 15.09.2026 Updated: 15.09.2026

ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-role user can submit POST /api/v1/command/{database} with language: js because PolyglotQueryEngine.command, PolyglotQueryEngine.analyze, and PolyglotQueryEngine.registerFunctions do not enforce database-administrator authorization. GraalPolyglotEngine also permits scripts to bypass the allowedPackages whitelist by reflecting from the bound database object through database.getClass().getClassLoader().loadClass to arbitrary host classes. These cooperating defects allow a read-only database user to read arbitrary host files outside the database scope. Process creation is already blocked, so OS command execution is not confirmed. The issue is distinct from CVE-2026-44221, CVE-2026-54076, and CVE-2026-54077. This issue is fixed in version 26.7.1.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CVSS Score: 7.7

Product Status

Vendor ArcadeData
Product arcadedb
Versions
  • Version < 26.7.1 is affected
Vendor com.arcadedb
Product arcadedb-server
Versions
  • Version < 26.7.1 is affected

References

Problem Types

  • CWE-269: Improper Privilege Management CWE
  • CWE-863: Incorrect Authorization CWE